Analytics BIOC Low

Azure account deletion by a non-standard account

An Azure AD account deletion was performed by a user that doesn't typically delete users.

Module:
Identity Threat Detection (ITDR), SaaS Threat Detection
Licensed by:
Identity Threat Detection (ITDR)
Data source:
AzureAD Audit Log
ATT&CK tactics: Impact (TA0040)
ATT&CK techniques: Account Access Removal (T1531)
Attacker's goals:

Interrupt availability and access to Azure by deleting access accounts.

Investigative actions:

Follow further actions by the initiator. Check what services, groups and applications are affected by the deleted user being removed. Check if the deleted user had a privileged role.

Test period:
N/A (single event)
Deduplication:
1 Day
2 variations:
  • Azure account deletion by a non-standard account with high administrative activity Informational (parent: Low)
  • A suspicious Azure account deletion by a non-standard account Medium (parent: Low)